Tag: EKS
All the articles with the tag "EKS".
Selecting more than one tag in the sidebar shows only posts that have every selected tag.
- #Kubernetes#EKS#Hoodi
Kubernetes Namespace Design for a Hoodi Validator
A security-focused guide to designing Kubernetes namespace boundaries for a Hoodi validator architecture.
6 min read - #Vault#Kubernetes#EKS
Vault Architecture on Kubernetes
A practical guide to Vault architecture, workload identity, secret delivery, PKI, and operations on Kubernetes.
8 min read - #AWS#ECR#EKS
Private ECR Delivery Architecture for Private EKS
A defense-in-depth design for delivering approved private ECR artifacts to private EKS workloads.
Updated:15 min read - #AWS#EKS#Kubernetes
EKS Security Controls Implemented in the Cluster Design
A technical overview of EKS security controls implemented across the cluster design.
8 min read - #Ethereum#Hoodi#AWS
Private EKS Security Design Review
A confidentiality-focused security design review of a private EKS environment.
10 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (10) - Regulatory Overlays
Applying PIPA/ISMS-P and customer contractual obligations on top of the EKS SaaS baseline, and why tenant deletion is a control-plane workflow, not a single DynamoDB delete.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (9) - CI/CD Verification
Gating EKS SaaS deployments on requirement IDs, from rendering Helm and Kustomize manifests to running tenant-boundary tests across Cognito pools.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (8) - Evidence and Review
Why an EKS SaaS requirement is a criterion rather than proof, and how the plugin ties NetworkPolicy, IRSA, and tenant-context requirements to evidence-based status.
2 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (7) - Refresh and Lifecycle
Refreshing the EKS SaaS security contract as ingress, cluster topology, and IAM bindings change, without losing prior approvals, evidence, or requirement history.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (6) - Authoring, Validation, and Publication
Writing atomic, verifiable EKS SaaS requirements for tenant identity, network isolation, IRSA, and the provisioning pipeline, validated by code before publication.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (5) - Responsibility and Prioritization
Splitting EKS SaaS work across AWS, the platform team, product teams, and the SaaS operator, and why IRSA and shared controllers need more than one owner.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (4) - Blast Radius
Calculating blast radius across the AWS EKS SaaS reference architecture, from a contained siloed order table to a provisioning pipeline that can reach the whole account.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (3) - Threat Analysis
A ten-threat model across the AWS EKS SaaS reference architecture's shared control plane, tenant namespaces, ingress routing, and IAM Roles for Service Accounts.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (2) - CIA Impact and Baseline
Calculating CIA impact for the AWS EKS SaaS reference architecture, where pooled and siloed DynamoDB models and a shared control plane both feed the result.
7 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (1) - Service Analysis
Building a confirmed service profile for AWS's EKS SaaS reference architecture, where namespace-per-tenant isolation and a shared control plane change what counts as a boundary.
6 min read